NAIF Gravity Diagnostic — Free MCP/API/Webhook Triage
Server Details
Free MCP, API auth, webhook and schema diagnostics with bounded checks and safe quote routing.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- naief9961-tech/ai-growth-engine
- GitHub Stars
- 0
TDQS
Scored across 4 tools
Each tool targets a clearly distinct failure class: API 401 auth, JSON Schema mismatch, MCP lifecycle/transport, and webhook signature. The descriptions reinforce boundaries by specifying sanitized inputs and explicitly excluding repair or credential handling, so an agent can select without overlap.
All tool names follow the same snake_case diagnose_<domain>_<failure> pattern. There are no mixed conventions or vague verbs that would confuse selection.
Four tools is well-scoped for a focused diagnostic triage server. Each tool covers a separate failure domain, and there are no redundant or filler tools.
The surface covers several common failure classes across API, JSON Schema, MCP, and webhook diagnostics. However, API coverage is limited to 401 and webhook coverage is limited to signature/delivery, leaving other common failure modes such as non-auth API errors or broader webhook payload issues unhandled.
Available Tools
4 toolsdiagnose_api_auth_401Diagnose API Authentication 401AInspect
Diagnose a sanitized HTTP 401 authentication failure without accepting credentials or contacting the target endpoint.
| Name | Required | Description | Default |
|---|---|---|---|
| method | No | ||
| context | No | ||
| endpoint | No | Only scheme, host and path are retained; query and fragment are discarded. | |
| http_status | Yes | ||
| error_message | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| policy | Yes | |
| trace_id | Yes | |
| diagnosis | Yes | |
| confidence | Yes | |
| free_checks | Yes | |
| collision_id | Yes | |
| repair_scope | Yes | |
| evidence_hash | Yes | |
| failure_class | Yes | |
| quote_endpoint | Yes | |
| confidence_label | Yes | |
| repair_available | Yes | |
| secrets_redacted | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only cover safety hints; the description adds genuinely new behavior: it refuses credentials and never contacts the target endpoint, and it operates on sanitized input. That is useful disclosure an agent cannot infer from readOnlyHint/openWorldHint alone. One unresolved tension: readOnlyHint=false suggests a non-read-only operation even though the description implies a pure offline analysis.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with no filler; every clause (sanitized input, no credentials, no endpoint contact) earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The output schema exists so return values need not be explained, which lowers the burden. Still, with 5 parameters at 20% schema coverage and no per-parameter guidance in the description, an agent gets only a partial picture of how to shape the call.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 20% (just endpoint), so the description must carry the load, and it largely does not. It hints that error_message should be sanitized and that no credentials belong in the call, but says nothing about what 'context', 'method', or 'endpoint' expect beyond the schema's own notes.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (diagnose) plus a tightly scoped resource (a sanitized HTTP 401 authentication failure), which naturally separates it from the sibling tools (json_schema, mcp, webhook_signature). It does not explicitly name the siblings or draw the boundary, but the object of diagnosis is unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the usage context (you have a 401 auth failure to analyze) and adds two constraints — no credentials accepted, no contact with the target endpoint. However it never says when to prefer this tool over the sibling diagnose_* tools or what inputs make it applicable. Usage is implied rather than stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
diagnose_json_schema_failureDiagnose JSON / MCP Schema Type MismatchBInspect
Diagnose a bounded JSON Schema or MCP input-schema type mismatch using only sanitized paths and types; no raw payload is required.
| Name | Required | Description | Default |
|---|---|---|---|
| context | No | ||
| actual_type | No | ||
| schema_path | No | ||
| error_message | Yes | ||
| expected_type | No | ||
| instance_path | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| policy | Yes | |
| trace_id | Yes | |
| diagnosis | Yes | |
| confidence | Yes | |
| free_checks | Yes | |
| collision_id | Yes | |
| repair_scope | Yes | |
| evidence_hash | Yes | |
| failure_class | Yes | |
| quote_endpoint | Yes | |
| confidence_label | Yes | |
| repair_available | Yes | |
| secrets_redacted | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare destructiveHint=false and openWorldHint=true but also readOnlyHint=false and idempotentHint=false, which is a slightly surprising profile for a diagnostic tool and is neither explained nor contradicted by the description. The description does add genuine value beyond the annotations by stating the tool operates on sanitized paths and types and needs no raw payload, which is useful data-handling context, but it says nothing about what the diagnosis produces or its confidence.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single tight sentence with the core purpose and the key constraint front-loaded. Every clause earns its place and there is no padding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be described, which the description correctly omits. However, for a 6-parameter tool with no schema descriptions, no parameter explanation, and no routing guidance against the near-identical diagnose_mcp_failure sibling, the definition is only minimally complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 0% across 6 parameters, so the description carries the full burden. It gestures at 'sanitized paths and types', loosely covering schema_path/instance_path and expected_type/actual_type, but it never mentions the required error_message parameter or the free-form context field, and gives no format expectations for the paths.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description gives a specific verb (diagnose) and a precise resource (JSON Schema / MCP input-schema type mismatch), which is narrow enough to separate it from diagnose_api_auth_401 and diagnose_webhook_signature. It does not, however, draw a boundary against its closest sibling, diagnose_mcp_failure, leaving some ambiguity about which to pick for MCP-related errors.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no explicit when-to-use statement, no prerequisites, and no named alternative. The clause 'no raw payload is required' hints at an input constraint but is not framed as usage guidance, and no sibling is referenced to route the agent.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
diagnose_mcp_failureDiagnose MCP FailureAInspect
Diagnose sanitized MCP initialize, discovery, transport, capability and tool-schema failures. Returns bounded free checks and never performs a repair or payment.
| Name | Required | Description | Default |
|---|---|---|---|
| context | No | ||
| transport | No | ||
| error_code | No | ||
| error_message | Yes | ||
| protocol_version | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| policy | Yes | |
| trace_id | Yes | |
| diagnosis | Yes | |
| confidence | Yes | |
| free_checks | Yes | |
| collision_id | Yes | |
| repair_scope | Yes | |
| evidence_hash | Yes | |
| failure_class | Yes | |
| quote_endpoint | Yes | |
| confidence_label | Yes | |
| repair_available | Yes | |
| secrets_redacted | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Adds genuine behavioral context beyond the annotations: outputs are 'bounded free checks' (cost/scope guarantee) and it 'never performs a repair or payment'. This usefully narrows what the agent can expect even though annotations carry destructiveHint=false and openWorldHint=true. There is mild tension with readOnlyHint=false (the description reads like a non-mutating inspection tool), but not a direct contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences with zero filler; the diagnostic scope is front-loaded and the non-mutation guarantee follows immediately. Every clause earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return-value explanation is unnecessary, and the description adequately covers the tool's domain and safety envelope. But for a 5-parameter tool with 0% schema coverage, it supplies no parameter-level guidance and no explicit routing to the sibling diagnosers, leaving real gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% across 5 parameters (error_message, context, transport enum, error_code, protocol_version), and the description contributes nothing about any of them — no guidance on the required error_message, the meaning of 'context', or the transport enum. The description entirely fails to compensate for the coverage gap.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('Diagnose') and a well-scoped resource: MCP initialize, discovery, transport, capability and tool-schema failures. This is clearly distinct in domain from the sibling diagnosers (auth 401, JSON schema, webhook signature), but the description never names or contrasts those siblings, so an agent must infer the boundary itself.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Returns bounded free checks and never performs a repair or payment' establishes an important exclusion (no repair, no cost) and implies this is a safe diagnostic entry point. However, there is no explicit 'use this when X, use diagnose_api_auth_401 when Y' routing, and no statement of prerequisites such as needing a captured error message.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
diagnose_webhook_signatureDiagnose Webhook Signature FailureBInspect
Diagnose a sanitized webhook signature/delivery failure without accepting the raw payload, signature value or signing secret.
| Name | Required | Description | Default |
|---|---|---|---|
| context | No | ||
| retry_count | No | ||
| error_message | Yes | ||
| payload_size_bytes | No | ||
| signature_header_present | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| policy | Yes | |
| trace_id | Yes | |
| diagnosis | Yes | |
| confidence | Yes | |
| free_checks | Yes | |
| collision_id | Yes | |
| repair_scope | Yes | |
| evidence_hash | Yes | |
| failure_class | Yes | |
| quote_endpoint | Yes | |
| confidence_label | Yes | |
| repair_available | Yes | |
| secrets_redacted | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations (readOnlyHint=false, openWorldHint=true, destructiveHint=false) give the safety profile, and the description adds non-obvious context that is not in any structured field: the tool deliberately refuses raw payloads, signature values, and signing secrets. That sanitization constraint is genuinely useful behavioral information for an agent deciding what to pass.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single tight sentence with the scope constraint front-loaded and no filler. It is efficient, though its brevity is partly achieved by omitting input guidance rather than by disciplined editing.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be described. Still, for a 5-parameter, 0%-coverage diagnostic tool, the description omits what each input should contain and any prerequisites or typical error classes, leaving the agent with limited operational guidance.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% across 5 parameters, so the description must compensate and largely does not. It only hints at exclusions (no raw payload/signature/secret), leaving context, retry_count, payload_size_bytes, signature_header_present and the required error_message format entirely unexplained.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (diagnose) and resource (webhook signature/delivery failure), and the resource scope distinguishes it from siblings like diagnose_api_auth_401 and diagnose_json_schema_failure, though it never names them explicitly.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Usage is implied by the name and description: call it when a webhook signature or delivery fails. However, there is no explicit when-to-use vs. when-not guidance and no routing to the sibling diagnose_* tools, which an agent must infer from tool names alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
4 tool updates
- First observed
diagnose_api_auth_401 - First observed
diagnose_json_schema_failure - First observed
diagnose_mcp_failure - First observed
diagnose_webhook_signature
Related MCP Connectors
Collision-first MCP diagnostics for MCP, API, webhook and agent failures. Returns structured evidence, bounded repair guidance, agent compatibility checks and safe recovery routing.
Free MCP tools: the only MCP linter, health checks, cost estimation, and trust evaluation.
Paid remote MCP for context-budget routing, schema cost estimates, usage audits, and readiness.
Check an MCP endpoint resolves: liveness, live tool list, schema drift. Free.
Related MCP Servers
- FlicenseNot gradedqualityAmaintenanceRead-only MCP server that performs deterministic local preflights of agent-payment boundary documents and x402 v2 PaymentRequired JSON, and prepares unsubmitted public quote-request drafts without network calls or fund movement.-
- AlicenseNot gradedqualityAmaintenanceEnables free, read-only checks of AI agents and MCP servers for conformance, published changes, delivery evidence, and verifiable receipts without requiring an account or API key, using public or non-personal data only.MIT
- AlicenseAqualityBmaintenanceAutonomous synthetic health checks, JSON-RPC 2.0 handshake validation, breaking schema drift detection, and credential leak scanning for remote MCP servers.38 npm1Apache 2.0
- AlicenseAqualityBmaintenanceA Model Context Protocol server that gives any MCP client two economic-safety tools: realizable quote and pretrade check, paid per call in USDC with no accounts.295 npmMIT
Glama MCP Gateway
Add one secure layer between your agents and this server.